LL::NG can use federation protocols (SAML, CAS, OpenID) independently to:
So you can configure it to authenticate users using a federation protocol and simultaneously to provide identities using other(s) federation protocols.
Schemes validated:
Note that OpenID-Connect consortium hasn't already defined single-logout initiated by OpenID-Connect Provider. LLNG will implement it when this standard will be published.
See the following chapters: